Compliance
GDPR and meeting minutes: local processing and an audit trail
August 10, 2026 · 4 min read · Navin team
Roles, minimisation, retention, erasure: how to document an AI meeting minutes chain with the Navin Meeting module, its explicit processors, and its exportable local log.
Recording a meeting means processing personal data: voices, statements, judgements about people, sometimes sensitive categories. So the question is not "is the tool compliant", it is "can I document my processing chain". The Meeting module in Navin is built so that the answer fits on one page: local by default, processors you choose yourself, and an exportable audit trail.
Docs: Privacy and audit · Meeting · Calendar
Who is who in the chain
GDPR thinks in roles. On the #/meeting desk the split is explicit, because no component is imposed on you.
| Role | Who | Practical consequence |
|---|---|---|
| Controller | You, or your organisation | You decide purpose and retention |
| Transcription processor | The STT provider you configured | Name it in your processing record |
| Summary processor | The chat model you selected | Name it too, including a local one |
| Meeting hosting | Your machine | No transfer by default |
Navin operates no meeting archive and adds no hidden recipient: if you never record and never run an action, nothing leaves the machine.
Minimise for real, not symbolically
The most effective minimisation is not producing the data at all. Three habits cover most cases:
- Notes without audio. Actions accept notes alone, so a sensitive HR meeting can produce minutes without any recording ever existing.
- Numbered speakers. Identification actions never invent names; without an explicit introduction you stay on Speaker 1 and Speaker 2, which is often enough.
- A template that frames the output. A template asking for decisions and actions, without judgements about people, keeps the produced data aligned with its purpose.
What stays on the machine
| Data | Location | Leaves the machine? |
|---|---|---|
| Meeting list, transcripts, summaries | Local application profile | No |
| Custom templates | Local profile | No |
| Calendar events and conference links | Local profile, parsed from your .ics | No |
| Audit trail | Local profile | No, unless you export it |
| Audio segments | Sent on demand | Only to your STT provider |
Deleting a meeting removes it from storage. Clearing the application data removes meetings, templates, calendar, and log in one move, which gives you an erasure procedure that is easy to describe in an internal policy.
The audit trail as evidence
Every meaningful action is logged locally, append-only, with a timestamp, the meeting identifier, the action, and a short detail: meeting created or deleted, recording started and stopped, audio imported and transcribed, template selected, action sent to the agent, export produced, calendar imported, event joined.
The log exports as Markdown from the Export tab and answers what an auditor actually asks: what was captured, when, with which processor, and who requested the output. It is not a security boundary, since it lives alongside the data it describes, but it is a verifiable trace, which cloud meeting assistants rarely hand you.
Checklist before rolling this out to a team
- Name the STT and model processors in your processing record.
- Set a retention period, and treat the desk as a workspace: export, archive, delete.
- Inform participants before recording. Navin shows a timer during capture but announces nothing inside the call.
- Forbid recording for the data categories your policy excludes, and prefer notes there.
- Attach the audit trail to the export for meetings with contractual or legal weight.
- Check provider locations if your policy requires a specific region.
This article describes product mechanics, not legal advice: your impact assessment remains yours.
FAQ
Is Navin GDPR compliant?
Compliance is a property of your processing, not of an isolated piece of software. Meeting provides the building blocks that make it demonstrable: local processing, explicit processors, simple erasure, exportable log.
Where is meeting data stored?
In the local application profile, under dedicated keys documented on the Privacy page. No background sync.
Can I use a fully local model?
Yes. If your STT and chat providers run on your own infrastructure, no meeting data leaves your network.
How do I answer an erasure request?
Delete the meeting from the list, remove the exported files from the delivery folder, and keep the record of that operation in your own register.
Can a participant refuse to be recorded?
Yes, and that should be the default posture: switch to note taking, the actions still produce minutes.
Download Navin · Privacy docs · Local AI meetings · Your API keys stay on your machine
Try Navin on your machine
Local agent, cross-platform. Code, debug, scrape, leads, security and review - without leaving Navin.